PinpostSign inCreate a free account

Security and subprocessors

Where your data lives, who can access it, and what protects it. This is the page referenced by the privacy policy and the data processing agreement.

Subprocessors

This is the complete list of providers that process data on Pinpost's behalf. Each is bound by protection obligations equivalent to ours.

ProviderRoleEstablishmentData storage
SupabaseBase de données, authentification, fichiersSingapourUnion européenne, région Francfort
VercelHébergement de l'application et du siteÉtats-UnisUnion européenne, région Francfort
StripePaiementIrlande et États-UnisUnion européenne
ResendE-mails transactionnelsÉtats-UnisUnion européenne, région européenne
SentryErreurs techniquesÉtats-UnisUnion européenne, région européenne
PlausibleMesure d'audience sans cookieUnion européenneUnion européenne
Meta (Facebook)Mesure publicitaire par pixel, avec consentement (CookieBanner.tsx)Irlande et États-UnisÉtats-Unis

Any addition to this list is subject to 30 days' notice, announced by email. During that period an agency may object in writing and, failing agreement, terminate at no cost.

Technical and organisational measures

Per-organisation isolation enforced at the database level: one organisation cannot read or write another's data, even if the application code gets it wrong. This rule is checked automatically on every change.

Encryption in transit and at rest.

Access and action log, kept for twelve months.

Daily backups, with a quarterly restore test.

Administrator access limited to metadata. Pinpost requests no access to your social network accounts, and therefore stores no token.

Transfers outside the European Union

Data is stored in the European Union, in the Frankfurt region. Some providers are established outside the EU and access from their home establishment remains possible for maintenance and support. These transfers are governed by the European Commission's standard contractual clauses, supplemented where applicable by the EU–US Data Privacy Framework. A copy of these safeguards is available on request at privacy@pinpost.cc.

In the event of a data breach

We notify the CNIL within 72 hours and inform the people concerned as soon as possible where the breach is likely to result in a risk to their rights and freedoms. A client agency is notified within 48 hours of discovery.

Report a vulnerability

Write to security@pinpost.cc. We acknowledge receipt without delay and keep you informed. No action will be taken against research conducted in good faith, without data exfiltration or degradation of the service.

If you received an approval link

You have no Pinpost account, your details were passed to us by the agency that invited you, and we use them only to show you the content and record your answer. The corresponding section of the privacy policy details what is collected and for how long.

Read the section that concerns you